DesignKompanie

A studio service

Supplier CoA intake & incoming QC for SAP QM certificates read, checked and recorded against the inspection lot.

SAP QM holds the specification, the inspection lot and the usage decision. What happens before that is manual: someone reads a supplier's PDF certificate and types the values in. We build intake that reads the certificate, compares it with the SAP specification, shows the reviewer every value with its source on the page, and records the confirmed results on the inspection lot.

Supplier CoA intake & incoming QC for SAP QM

The facts behind this module

21 CFR 211.82(b)

“Components, drug product containers, and closures shall be stored under quarantine until they have been tested or examined, whichever is appropriate, and released.”
Source: US FDA, 21 CFR 211.82(b).

21 CFR 211.184(a)

Records shall include “the identity and quantity of each shipment of each lot of components, drug product containers, closures, and labeling; the name of the supplier.”
Source: US FDA, 21 CFR 211.184(a).

39 → 111

FDA CDER warning letters on manufacturing or GMP subjects rose from 39 in 2023 to 78 in 2024 and 111 in 2025.
Source: US FDA CDER data, as reported by PharmaSource.

Quoted from the sources linked. We add no estimates of our own.

What it looks like

CoA review — lot L-55120, cell culture medium

Values read

12

Within spec

11

Out of spec

1

Awaiting confirmation

12

ParameterSpecificationCertificate valueRead fromStatus
pH7.0 – 7.47.2Page 1Matched
Osmolality280 – 320 mOsm/kg301Page 1Matched
Endotoxin≤ 1.0 EU/mL1.4Page 2Out of spec
SterilityPassPassPage 2Matched

Interface concept with invented sample data, shown to illustrate the design. It is not a screenshot of a live system.

How it connects

SAP S/4HANA

  • Batches, QM, EWM, planning
  • Stays the system of record
  • Core left standard, nothing changed inside
released APIs only

The app, in your tenancy

  • SAP BTP, Azure or AWS, your region
  • Audit trail, roles, single sign-on
  • Read-only in a Pilot; write-back by agreement
scoped access

People and plant systems

  • Your teams, by role
  • Sponsors, each to their own data
  • MES, LIMS, QMS and logger platforms

SAP's clean-core rule, quoted: “Extensions must be developed using only released local or remote public SAP APIs, BAdIs, or ABAP RESTful application programming model business object (BO) extension points.” SAP PRESS, SAP S/4HANA Clean Core: Principles, Benefits, and Best Practices.

N° 01What SAP already covers

We start from SAP, not against it.

SAP QM manages inspection lots, specifications, results recording and usage decisions, and the approved source list controls who you buy from. This module adds reading of supplier PDF certificates and handling of supplier change notifications. This module is a side-by-side extension: it reads and writes SAP only through released APIs and leaves the core standard.

N° 02Where it helps

Four situations this module is built for.

01

Values typed from PDFs

Read from the certificate, checked against the spec, confirmed by a person.

02

Out-of-spec found late

Flagged at intake before results are recorded.

03

Change notifications in email

An owner, an impact assessment and a decision, with the affected materials from SAP.

04

Supplier history scattered

Results by supplier and material over time.

N° 03What the module covers

Scope, in plain terms.

01

CoA intake

PDF certificates read and matched to the SAP inspection lot.

02

Spec check

Each value compared with the SAP QM specification.

03

Results recording

Confirmed values posted to the inspection lot through SAP APIs.

04

Supplier changes

Change notifications with assessment and decision.

N° 04For each person in the decision

One page, six readers.

01

Supply chain lead

The scope above, three fixed-scope packages with prices, and a read-only Pilot you can run on one site before committing.

02

QA and validation

GAMP 5 Category 5 development documents, executed developer IQ/OQ evidence, Annex 11 and Part 11 controls in the GxP-ready package. You run and sign validation.

03

IT and your SAP team

Released SAP APIs only, no changes inside SAP, one least-privilege technical user, deployed in your own tenancy and region.

04

Sponsor-facing teams

Each sponsor sees only their own data, enforced in the data layer, with every access logged.

05

Procurement

Fixed scope and price per package, a written not-included list, and our vendor questionnaire answered in full on request.

06

Finance

The price shown is ours. SAP licences, including any SAP Digital Access for documents created in SAP, hosting and validation effort are yours and are listed as not included.

N° 05The Pilot, week by week

Eight to ten weeks, read-only from SAP.

01

Weeks 1–2: scope and access

Requirements workshop, the list of SAP APIs to be read, a technical user from your SAP team, and sample data agreed.

02

Weeks 3–5: build

The module built in your tenancy against your SAP test system, with a working demo every week.

03

Weeks 6–7: your data

Connected to the agreed SAP data, tested by your users, findings fixed.

04

Weeks 8–10: live on one site

Go-live for up to 25 users, a handover session, and a written decision paper for the Production package.

N° 06Your three options

Inside SAP, packaged, or beside SAP.

01

Customise inside SAP

Done by your SAP partner. SAP's clean-core rule limits extensions to released APIs and extension points, and each change follows your SAP change and validation process.

02

Buy a packaged product

A vendor's standard product and roadmap, with its own licence, validation package and integration to your SAP.

03

Build beside SAP (this page)

An app scoped to your process, in your tenancy, connected through released SAP APIs, with the source code and documentation handed to you.

N° 07AI assists

Where AI helps, and where a person decides.

Designed to the draft EU GMP Annex 22: predictive models are static, versioned and show their confidence; generative tools only draft for a person to confirm. No assist releases, rejects or ships a lot.

01

Certificate reading

Values extracted from each PDF and shown next to the original for a reviewer to confirm. Generative, non-critical by design: nothing is recorded until a person confirms it.

02

Supplier trend watch

A static model flags drifting results by supplier and parameter, with confidence, before they fail.

N° 08Investment

Pilot, production, or GxP-ready.

Pilot

From $32,000

One site, read from SAP through released APIs, live in 8–10 weeks.

  • CoA reading and spec check for selected materials
  • Reviewer screen with source highlighting
  • Read-only connection to SAP S/4HANA (OData APIs and CDS views), no core changes
  • Audit trail on every record, role-based access, SSO with your identity provider
  • One site, up to 25 named users
  • Not included: write-back to SAP, electronic signatures, validation documentation, SAP BTP licences
Start the project
Recommended

Production

From $52,000

Two-way with SAP and one more plant system, across sites.

  • Everything in Pilot
  • Results posted to SAP QM inspection lots
  • Supplier change-notification workflow
  • Two-way integration through SAP APIs or SAP Integration Suite, clean-core compliant
  • Digital Access check with your SAP licence team before any write-back is switched on
  • Up to three sites and 250 users
  • 60 days of hypercare after go-live
  • Not included: validation documentation, SAP or BTP licences (including any SAP Digital Access your contract requires for documents created in SAP), SAP-side configuration by your SAP partner
Start the project

GxP-ready

From $84,000

Built and documented for GMP use.

  • Everything in Production
  • 21 CFR Part 11 / EU Annex 11 electronic signatures and record controls
  • GAMP 5 Category 5 SDLC pack: URS trace matrix, FS/DS, code review records
  • IQ/OQ scripts with executed developer evidence; change control for later releases
  • Not included: validation execution and QA sign-off (your CSV team), hosting qualification, SAP licences
Start the project

Before you buy

What you get

  • An independent build that connects to SAP only through SAP's released APIs
  • A read-only Pilot that creates nothing in SAP, so it carries no SAP licence exposure
  • Delivery alongside your SAP partner and IT, who keep control of SAP itself

What we don’t do

  • SAP licences, or SAP Digital Access for documents a two-way build creates in SAP
  • Changes to your SAP configuration or custom code inside SAP
  • SAP certification of the integration, unless you ask us to scope it in

DesignKompanie is an independent studio and is not affiliated with, endorsed by or a partner of SAP SE. SAP and SAP S/4HANA are trademarks of SAP SE.

N° 09Questions

The answers we give most often.

Does AI make the usage decision?
No. The usage decision stays in SAP QM with QA. AI only prepares the values a person confirms.
Is reading certificates allowed under Annex 22?
Generative AI is permitted for non-critical tasks with a human in the loop. Intake is designed that way: every value is confirmed before it is recorded.
Does it replace our QMS?
No. It covers certificate intake and supplier changes and links to your QMS for deviations.
Are you an SAP partner?
No. We are an independent studio. We build beside SAP using its released APIs and work with your SAP partner, who stays responsible for SAP itself. If you need the integration certified by SAP, we scope that into the project.

Start your book

Planning the Supplier CoA intake for SAP QM build?

Tell us your sites, the systems you run and what has to change. You'll get a scoped plan and a fixed price within two business days.

Supplier CoA Intake & Incoming QC for SAP QM